/ Sep 20, 2026
Trending
A security researcher has publicly detailed a new Windows vulnerability that can grant attackers full system access, bypassing a recent patch and escalating an ongoing dispute with Microsoft. The flaw, named ShieldBreak, was disclosed by the researcher known as Nightmare Eclipse, who has previously released several other Windows bugs.
The vulnerability resides in Windows Defender, the built-in security engine. An attacker can exploit it to elevate privileges from a low-level user to complete control over the device and its data. The proof-of-concept is a Windows app that requires the user to run it. It affects Windows 10, Windows 11 (including the latest 25H2 version), and Windows Server 2025.
Independent security researcher Will Dormann confirmed the exploit works, noting that Windows Defender must be enabled for the attack to succeed.
This new exploit builds on a previous one called RoguePlanet, for which Microsoft issued a patch. Nightmare Eclipse claims this patch is insufficient, and ShieldBreak demonstrates a full bypass of that fix.
Microsoft has not yet released a patch for ShieldBreak. A spokesperson did not comment when contacted. Because the flaw was disclosed before Microsoft could address it, it is considered a zero-day vulnerability.
The disclosure is the latest in a series of public releases by Nightmare Eclipse, who has criticized Microsoft’s handling of their bug reports. In May, Microsoft threatened legal action against researchers who disclose zero-days outside its policies, a stance that drew criticism from the security community and was later walked back in a social media post, though the original blog post remains unchanged.
ShieldBreak was released a day after Microsoft’s monthly Patch Tuesday updates, which this month addressed around 500 bugs, a figure the company attributes to its increased use of AI in vulnerability discovery.
Disclaimer: This post is for informational purposes only and is based on publicly available reports. The image is AI generated and is just for reference.
#WindowsSecurity, #ZeroDay, #CyberSecurity, #Microsoft
It is a long established fact that a reader will be distracted by the readable content of a page when looking at its layout. The point of using Lorem Ipsum is that it has a more-or-less normal distribution
Copyright PopularTechNews. 2024